CVE-2023-5169Out-of-bounds Write in Mozilla Firefox

CWE-787Out-of-bounds Write14 documents8 sources
Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.2%
top 52.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateOct 11

Description

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified118
NVDmozilla/firefox< 118
CVEListV5mozilla/firefox_esrunspecified115.3
NVDmozilla/firefox_esr< 115.3
Ubuntumozilla/firefox< 118.0.1+build1-0ubuntu0.20.04.1+1

Also affects: Debian Linux 10.0, 11.0, 12.0, Fedora 39

Patches

🔴Vulnerability Details

6
OSV
firefox regressions2023-10-11
OSV
firefox vulnerabilities2023-10-03
OSV
thunderbird vulnerabilities2023-10-03
OSV
CVE-2023-5169: A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially ex2023-09-27
GHSA
GHSA-65f9-wqxf-mh9r: A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially ex2023-09-27

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-10-03
Ubuntu
Firefox vulnerabilities2023-10-03
Red Hat
Mozilla: Out-of-bounds write in PathOps2023-09-26
Debian
CVE-2023-5169: firefox - A compromised content process could have provided malicious data in a `PathRecor...2023
Mozilla
Mozilla Foundation Security Advisory 2023-43: CVE-2023-5169
CVE-2023-5169 — Out-of-bounds Write in Mozilla Firefox | cvebase